View notices
Sunday, 6 September 2026 · City EditionNewsroom
The Fiduciary GazetteA newspaper of record for the professions
News

SA now Africa's leading target for cybercrime – Interpol

By African News Agency · 4 August 2026
SA now Africa's leading target for cybercrime – Interpol

Interpol's African Cyberthreat Assessment Report has found that South Africa has become the primary focal point of cybercriminal activity on the continent, shifting from an opportunistic target to a hub for industrialised, high-impact digital attacks.

Rapid digital adoption, advanced subsea cabling and a deeply integrated financial sector have made the country's digital ecosystem a high-value target for transnational syndicates, executive fraud networks and infrastructure sabotage.

Key figures from the report include that ransomware detections at 92% of all such detections in Africa are concentrated in South Africa.

Business email compromise (BEC) is 70% of continental detections originate there, system vulnerabilities at 43.6% of all identified exploitable vulnerabilities on the continent, phishing accounted for 40% of African detections, digital sextortion generated 30% of related IP senders and detections continent-wide, and DDoS attacks recorded 213,523 cases, with bandwidth peaks reaching 312 Gbps.

Ransomware targeting South African organisations has shifted from straightforward extortion toward disrupting critical infrastructure. 

One cited case involved an attack on the South African Weather Service, which damaged meteorological data systems and caused delays to regional aviation routing and maritime navigation. 

The report notes attackers increasingly use automated reconnaissance tools and unpatched VPNs to steal credentials before deploying payloads.

South Africa is also identified as an operational base for BEC networks active since 2017, which use AI to craft executive email lures convincing enough to deceive companies in the US and Europe, with proceeds laundered through mule networks and crypto exchanges. Separately, automated botnets based in the country drive mass-scale sextortion campaigns demanding cryptocurrency payments.

Compromised personal data from local breaches feeds dark web markets, where fraudsters combine it with AI tools to build synthetic identities capable of bypassing standard KYC checks to open fraudulent accounts and secure credit.

South Africa's regulatory framework – anchored by the Cybercrimes Act and its 72-hour breach disclosure rul – is comprehensive, but enforcement remains constrained.

Slow Mutual Legal Assistance Treaty processes hamper cross-border prosecutions, and public agencies face capacity gaps in real-time threat intelligence, AI-driven mitigation and cryptocurrency tracing, despite relatively high cybersecurity spending compared with regional peers.

SOURCE: African News Agency

LINK: https://africannewsagency.com/south-africa-named-africas-cybercrime-hotspot/

PHOTO CREDIT: Controllit